🇩🇪
NihiliousMonk
2026-09-06 06:17:14
(2 hours ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:21:03
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:20:59.477842 2026] [security2:error] [pid 14893:tid 14893] [client 34.182.131.115:58782] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cajunfriedturkey.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cajunfriedturkey.com"] [uri "/backup.sql"] [unique_id "apzqK6dzYtdIUjW6LRHsPQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:31
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:26.765588 2026] [security2:error] [pid 15203:tid 15203] [client 34.182.131.115:57338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jsdavison.com"] [uri "/.env.prod"] [unique_id "apzjPr44ulWo85EG4IzbwAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:59:24
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:18.990469 2026] [security2:error] [pid 31718:tid 31718] [client 34.182.131.115:45682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.savannah-house.com"] [uri "/.env.backup"] [unique_id "apzXBpIMTNiekyz6GihRuQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 02:58:55
(6 hours ago)
Attempted access to sensitive endpoint (/.env.dev) detected. Automated scan or unauthorized probing.
Web App Attack
🇳🇴
jad-abuse
2026-09-06 01:35:33
(7 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_u ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_ua, source_backup, actuator, env_probe, ignition_debug, config_backup. Observed by 1 sensor(s); 26 hits.
show less
Hacking
Web App Attack
🇮🇩
Burayot
2026-09-06 00:50:30
(8 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.182.131.115 (US/United States/11 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.182.131.115 (US/United States/115.131.182.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇫🇷
✨
2026-09-06 00:34:08
(8 hours ago)
Domain : dataforms.co.uk
Rule : hack
2026-09-06 00:32:46 ***hidden-privacy*** GET /Admin/phpinfo.php ...
show more
Domain : dataforms.co.uk
Rule : hack
2026-09-06 00:32:46 ***hidden-privacy*** GET /Admin/phpinfo.php - 443 - 34.182.131.115 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36 - dataforms.co.uk 301 0 0 460 182 107 - -
show less
Hacking
SQL Injection
Brute-Force
🇨🇭
4server
2026-09-06 00:23:33
(8 hours ago)
[SunSep0602:23:27.0807442026][security2:error][pid2404536:tid2404572][client34.182.131.115:0]ModSecu ...
show more
[SunSep0602:23:27.0807442026][security2:error][pid2404536:tid2404572][client34.182.131.115:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"landingswiss.ch.81-17-25-250.cpanel.site\"][uri\"/.env.old\"][unique_id\"apyyf6gSATa-foWZrUTJJAAAAVU\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:21:54
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:21:51.658613 2026] [security2:error] [pid 24037:tid 24037] [client 34.182.131.115:54170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lambert-heating-and-air.com"] [uri "/.env.backup"] [unique_id "apyyH7rMnno94oBSCBuKkQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-06 00:16:33
(8 hours ago)
34.182.131.115 - - [06/Sep/2026:02:16:32 +0200] "GET /.env.prod HTTP/1.1" 404 4616 "-" "crusader-wor ...
show more
34.182.131.115 - - [06/Sep/2026:02:16:32 +0200] "GET /.env.prod HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.182.131.115 - - [06/Sep/2026:02:16:32 +0200] "GET /actuator/configprops HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.182.131.115 - - [06/Sep/2026:02:16:32 +0200] "GET /.env.bak HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇫🇷
dynamix
2026-09-05 23:21:53
(9 hours ago)
Multiple WAF Violations
Web App Attack
🇲🇾
Rizzy
2026-09-05 23:05:07
(9 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:43:13
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.131.115 (115.131.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:43:08.418740 2026] [security2:error] [pid 5412:tid 5412] [client 34.182.131.115:53162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hawkeyeibp.com"] [uri "/.env"] [unique_id "apya_HyesHO6bXCJskHo3wAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:02:33
(10 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack